5.4.1 Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks
Processes and automated mechanisms are in place to detect and protect personnel against phishing attacks.
5
artefacts
1
held by a system
3
at each review
hard
to go live
Identity provider / directory
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Configuration evidence for each mechanism, showing the action taken on detection · Cloud console / configuration management
periodic reviewEvidence produced at each review
- Documentation of the automated mechanisms deployed to detect and protect against phishing, such as mail authentication enforcement, link and attachment inspection and impersonation controls · Identity provider / directory
- Records of phishing detections and the outcome of each during the period · Document repository
- Evidence coverage extends to all personnel with access to system components, including contractors and privileged administrators · Identity provider / directory
governing documentDocuments that govern the control
- Processes complementing the mechanisms, such as reporting routes and response to a reported phish · Document repository
First move
Mostly documents and reviews. Pull the 1 system-held artefact from your Cloud console / configuration management on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.
Common gaps auditors find
- Awareness training presented as the control, where the requirement calls for automated mechanisms as well as processes
- Mail authentication published in monitor mode rather than enforcing, so spoofed senders still arrive
- Protection applied to corporate mail while collaboration platforms and personal device access are uncovered
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet5.3.5 Anti-malware cannot be disabled by users · 6.1.1 All security policies and operational procedures that are identified in Requirement 6 are: • Documented. • Kept up to date. • In use. • Known to all affected parties